Skip to content
@step-security

StepSecurity

Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner

Step Security Logo

Close the CI/CD Security Gap

Pinned Loading

  1. harden-runner harden-runner Public

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…

    TypeScript 1k 92

  2. dev-machine-guard dev-machine-guard Public

    Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages — in seconds.

    Shell 47 7

  3. secure-repo secure-repo Public

    Orchestrate GitHub Actions Security

    Go 311 50

  4. github-actions-goat github-actions-goat Public

    GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

    JavaScript 496 303

Repositories

Showing 10 of 277 repositories
  • repo-sync-pull-request Public

    ⤵️ A GitHub Action for creating pull requests. Secure drop-in replacement for repo-sync/pull-request.

    step-security/repo-sync-pull-request’s past year of commit activity
    Shell 0 MIT 1 0 5 Updated Mar 23, 2026
  • import-codesign-certs Public

    GitHub Action for Importing Code-signing Certificates into a Keychain. Secure drop-in replacement for Apple-Actions/import-codesign-certs.

    step-security/import-codesign-certs’s past year of commit activity
    TypeScript 0 MIT 1 0 9 Updated Mar 23, 2026
  • agent Public

    Purpose-built security agent for hosted runners

    step-security/agent’s past year of commit activity
    Go 42 Apache-2.0 27 22 24 Updated Mar 23, 2026
  • create-issue-from-file Public

    A GitHub action to create an issue using content from a file. Secure drop-in replacement for peter-evans/create-issue-from-file.

    step-security/create-issue-from-file’s past year of commit activity
    TypeScript 0 MIT 1 0 1 Updated Mar 23, 2026
  • cypress-io-github-action Public

    GitHub Action for running Cypress end-to-end & component tests. Secure drop-in replacement for cypress-io/github-action.

    step-security/cypress-io-github-action’s past year of commit activity
    JavaScript 0 MIT 1 0 2 Updated Mar 23, 2026
  • auto-approve-action Public

    👍 GitHub Action for automatically approving GitHub pull requests. Secure drop-in replacement for hmarr/auto-approve-action.

    step-security/auto-approve-action’s past year of commit activity
    TypeScript 0 MIT 1 0 8 Updated Mar 23, 2026
  • setup-cocoapods Public

    Set up your GitHub Actions workflow with a specific version of Cocoapods. Secure drop-in replacement for maxim-lobanov/setup-cocoapods.

    step-security/setup-cocoapods’s past year of commit activity
    TypeScript 0 MIT 1 0 10 Updated Mar 23, 2026
  • setup-swift Public

    GitHub Action to setup Swift environment. Secure drop-in replacement for SwiftyLab/setup-swift.

    step-security/setup-swift’s past year of commit activity
    TypeScript 0 MIT 1 1 12 Updated Mar 23, 2026
  • github-actions-pr-is-linked-to-work-item Public

    Check for linked Azure DevOps work item. Secure drop-in replacement for danhellem/github-actions-pr-is-linked-to-work-item.

    step-security/github-actions-pr-is-linked-to-work-item’s past year of commit activity
    TypeScript 0 MIT 1 0 10 Updated Mar 23, 2026
  • setup-nasm Public

    GitHub Action to install NASM. Secure drop-in replacement for ilammy/setup-nasm.

    step-security/setup-nasm’s past year of commit activity
    JavaScript 0 MIT 1 1 8 Updated Mar 23, 2026

Top languages

Loading…

Most used topics

Loading…